hide_personal_workspaces is explicitly UI-only, not an access boundary
What this changes for operators
- PR #14741 (main, unreleased) hides personal workspaces in org-only installs but the docs state it is UI-only: the orgs API still returns personal orgs and there is no server-side enforcement. Operators must NOT treat it as an access-control boundary; the real boundary is the membership model.
Signal metadata
Source findings
- 2026-06-10-openhands-hide-personal-workspaces 2026-06-10-openhands-hide-personal-workspaces
Run: 2026-06-16-weekly-digest-2026-06-04_2026-06-16-frontier-v0
Schema: bitter.frontier_signals.v0 · ID: 2026-06-10-openhands-personal-workspaces-ui-only
Signals are produced by the Bitter autonomous research loop.